foodora.cz
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Usercentrics
Third-party hosts loaded (5)
- micro-assets.foodora.com×46
- images.deliveryhero.io×2
- www.googletagmanager.com×2
- app.usercentrics.eu×1
- cdnjs.cloudflare.com×1
Registration
- Registrar
- REG-MARKMONITOR
- Created
- 2015-04-24
- Expires
- 2027-04-23 337 days left
- Updated
- 2020-04-16
- Name servers
-
- clint.ns.cloudflare.com
- gwen.ns.cloudflare.com
DNS records live
- NS
-
- clint.ns.cloudflare.com
- gwen.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
v=DMARC1; p=quarantine; pct=100; rua=mailto:d5ea1768a1c4993@rep.dmarcanalyzer.com; ruf=mailto:d5ea1768a1c4993@for.dmarcanalyzer.com; fo=1;CKO=cli_u7wxnwvsmqyupia3x77hf42bqejamf-site-verification=-DrJ-n7zrjwBUidX1kGIbg
- Verified for
-
- Atlassian
- DocuSign
- Microsoft 365
- TeamViewer
- Zoom
Email authentication partial
- SPF
-
v=spf1 ip4:18.197.36.5 include:amazonses.com include:_spf.google.com include:mx.sap-deliveryhero.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:d5ea1768a1c4993@rep.dmarcanalyzer.com, mailto:dmarc_agg@vali.email; ruf=mailto:d5ea1768a1c4993@for.dmarcanalyzer.com; fo=1;policy: none (monitoring only) - DKIM
-
Show 4 DKIM selectors
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAlXLeMKXiqVSdhkNtHARTLW4pTZyxqnQTei9kuryrB1hXhz5Y6v750ydj2a6ZnD0tjSVBS4ZWExAhlJ… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmNbfjUkW5AUiNW3QGY++QfcUAgrlBbN9pS8/knDAV2EMLTC1HpjwS71J17zPRhoKaOgDHkjKDqggu5ikjq… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnDc69HT/3llBnMzea8ejELfvSiALgNRCbqLtIWjPCMpPSM+OAk1uCZE0DRhDSxwz8RijnvPrkn1dUgYSzM…
selectors probed - google:
Certificate (current)
R13
Expires in 31 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- findings
-
- short HSTS max-age
- CSP uses wildcard sources
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- content-security-policy
default-src 'self' *.incognia.com *.icg-in.com https://micro-assets.foodora.com; connect-src 'self' data: *.ingest.sentry.io *.fd-api.com *.deliveryhero.net *.deliveryhero.io https://d3t78t62rc3tw1.cloudfront.net https://images.dhmedia.io *.googleapis.com *.gstatic.com *.braze.com *.usercentrics.eu *.googletagmanager.com *.google-analytics.com stats.g.doubleclick.net *.incognia.com *.icg-in.com *.icg-in.info wss://*.incognia.com wss://*.icg-in.info wss://*.icg-in.com https://www.accounts.google.com https://adservice.google.com *.adservice.google.com https://adservice.google.com/pagead/regclk googleads.g.doubleclick.net stats.g.doubleclick.net *.googleadservices.com https://analytics.google.com *.analytics.google.com https://api.avo.app *.px-cloud.net *.hotjar.io *.googlesyndication.com *.google.at *.google.bd *.google.cy *.google.cz *.google.ch *.google.fi *.google.fr *.google.hu *.google.jp *.google.hk *.google.la *.google.my *.google.nl *.google.no *.google.ph *.google.pk *.google.pl- strict-transport-security
max-age=5184000; includeSubDomains